Anyconnect static IP address with SDI authentication
We use the RSA server to backend our user authentication for our Anyconnect home VPN users. There have been requests to have some of our home users have static IP addresses while on the Anyconnect. I have not been able to find a working example on how to get this to work while using SDI (RSA) authentication.
I have a generic /23 for my user VPN network, let's say 10.1.0.0/23 and I would like to perhaps maintain a block of 32 addresses for the purpose of static assignment. Currently my address assignment is done on the ASA itself through a local pool.
The basic flow of what I'm looking to do is:
StaticUser1 connects and is assigned 10.1.0.1 DynamicUser1 connects and is assigned 10.1.0.33
If a user does not have a static ip address assignment, they will be issued an IP from the local pool.
I guess I'm stumped in figuring out how to get the static IP address assigned to the users that need it, while maintaining the SDI/RSA authentication for all the users.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...